CWE-354

Medium likelihood

Improper Validation of Integrity Check Value

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

171 vulnerabilities with CWE-354
CVE-2026-31839 HIGH
striae >=0.9.22 <3.0.0 - Integrity Check Bypass via Manifest Hash Tampering
CVSS 8.2
CVE-2026-28402 HIGH
nimiq/core-rs-albatross <1.2.2 - Auth Bypass
CVSS 7.1
CVE-2026-26275 HIGH
httpsig-hyper <0.0.23 - Auth Bypass
CVSS 7.5
CVE-2026-26007 MEDIUM
cryptography < 46.0.5 - Insufficient Verification of Data Authenticity in Public Key Functions
CVSS 6.5
CVE-2026-25934 MEDIUM
go-git < 5.16.5 - Improper Validation of Integrity Check Value for .pack and .idx Files
CVSS 4.3
CVE-2025-11694 HIGH
Rockwell CompactLogix 5370 v36 - CIP Sequence Validation Denial of Service
CVE-2025-11543 CRITICAL
Sharp Display Solutions - Code Injection
CVSS 9.8
CVE-2025-33193 MEDIUM
NVIDIA DGX Spark GB10 - Info Disclosure
CVSS 5.7
CVE-2025-4616 LOW
Palo Alto Networks Prisma Browser - Privilege Escalation
CVE-2025-55155 MEDIUM
MantisBT < 2.27.2 - Information Disclosure via Unvalidated Email Address Change
CVSS 5.4
CVE-2025-54887 CRITICAL
jwe <1.1.0 - Confidentiality Disclosure
CVSS 9.1
CVE-2025-7096 HIGH
Comodo Internet Security Premium 12.3.4.8162 - Info Disclosure
CVSS 8.1
CVE-2025-39203 MEDIUM
MicroSCADA X SYS600 10.5-10.7 - Denial of Service via IEC 61850-8 Crafted Message
CVSS 6.5
CVE-2025-4418 MEDIUM
AVEVA PI Connector for CygNet <1.6.14 - Privilege Escalation
CVSS 4.4
CVE-2025-3479 MEDIUM
Forminator Forms - Custom Form Builder <1.42.0 - RCE
CVSS 5.3
CVE-2025-3247 MEDIUM
Contact Form 7 <6.0.5 - Order Replay
CVSS 5.3
CVE-2025-24148 MEDIUM
macOS <13.7.5-15.4-14.7.5 - Code Injection
CVSS 5.5
CVE-2025-25183 LOW
vllm < 0.7.2 - Cache Poisoning via Predictable Hash Collision
CVSS 2.6
CVE-2024-7402 HIGH
Netskope Client - Privilege Escalation
CVE-2024-46992 HIGH
Electron <30.0.5-31.0.0-beta.1 - ASAR Integrity Bypass
CVSS 7.8
CVE-2024-47573 MEDIUM
FortiNDR <7.4.2-7.0.6 - Privilege Escalation
CVSS 6.5
CVE-2024-47935 MEDIUM
TXOne Networks StellarProtect <3.2 - Privilege Escalation
CVSS 6.7
CVE-2024-56169 MEDIUM
nicmx fort_validator < 1.6.6 - Incomplete Route Origin Validation Data via Cache Fallback Failure
CVSS 5.3
CVE-2024-51141 HIGH
TOTOLINK Bluetooth Wireless Adapter A600UB - RCE
CVSS 7.8
CVE-2024-52550 HIGH
Jenkins Pipeline: Groovy Plugin <3990.vd281dd77a_388 - Improper Input Validation
CVSS 8.0
Details
Vulnerabilities 171
Exploit Likelihood Medium